CVE-2025-7005
Description
A malformed PE file triggers uncontrolled recursion in Gen Digital antivirus scanning, crashing the process on Windows, macOS, and Linux.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A malformed PE file triggers uncontrolled recursion in Gen Digital antivirus scanning, crashing the process on Windows, macOS, and Linux.
Vulnerability
Uncontrolled recursion vulnerability in the portable executable (PE) file scanner used by Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus. When the scanner processes a specially crafted malformed Windows PE file, the recursive logic does not terminate, leading to a stack overflow or excessive resource consumption. The issue affects all platforms (Windows, macOS, Linux) running virus definition builds before VPS 25031700. The vulnerable scanning code is delivered via the shared Gen Digital virus definition update stream [1].
Exploitation
An attacker must deliver a malformed PE file to a system running an affected product at a vulnerable definition level. No authentication or special privileges are required; the file could arrive through email, a web download, or any other means that triggers an on-access or on-demand scan. The scanner's recursive unpacking or parsing of the malformed PE structure consumes excessive stack or memory, causing the antivirus process to hang or crash.
Impact
Successful exploitation causes a denial of service (DoS) of the antivirus process. The scanner becomes unresponsive or terminates, leaving the system temporarily unprotected until the process is automatically restarted or manually relaunched. The crash does not grant code execution or privilege escalation; the effect is limited to loss of real-time protection until recovery.
Mitigation
The fix is distributed automatically through the Gen Digital virus definition update stream. Installations at or above VPS 25031700 are not vulnerable [1]. Users should ensure that automatic updates are enabled. No manual workaround exists beyond updating definitions. The advisory does not indicate any addition to the CISA KEV catalog.
AI Insight generated on Jun 12, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: < VPS 25031700
- Range: < VPS 25031700
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
0No linked articles in our index yet.